Internal Audit Requirements for Investments by IIOs under IFSCA Regulations
International Financial Service Centre Insurance Offices (IIOs) operating in GIFT IFSC are subject to a dedicated investment framework under the IFSCA (Investment by International Financial Service Centre Insurance Office) Regulations, 2022. These regulations govern how IIOs invest and manage their investment assets and prescribe requirements relating to investment limits, governance, risk management and internal controls.
An important element of this framework is the requirement for internal audit of investments. Regulation 16 specifically requires IIOs to maintain internal control systems, including internal audits for investment, in addition to external audits.
For insurance and reinsurance offices in GIFT IFSC, investment internal audit therefore becomes an important component of their overall compliance and governance framework.
What Do the IFSCA Regulations Require?
Regulation 16 deals with the management and control of investments by an IIO. The regulation requires the entire investment process to be overseen by an Investment Management Committee comprising persons with financial and actuarial backgrounds, duly authorised by the Board and possessing relevant knowledge and understanding of risks inherent in insurance or reinsurance business.
For an IIO established in an unincorporated form, investments may be undertaken by persons authorised by its parent entity, supported by appropriate reporting and review protocols.
Most importantly from an assurance perspective, Regulation 16(3) provides that the IIO should have internal control systems, including internal audits for investment, in addition to external audits.
The regulations therefore make internal audit part of the investment control architecture. However, Regulation 16 itself does not prescribe a detailed audit format, methodology or reporting template.
Objective of Internal Audit of Investments
An investment internal audit should go beyond verification of investment balances appearing in the financial statements.
Its primary objective should be to evaluate whether the IIO’s investment activities are being conducted in accordance with the applicable IFSCA regulations, the Board-approved Investment Policy and established internal controls.
The audit should assess whether investments are eligible, properly approved and within prescribed regulatory exposure limits. It should also review the reliability of investment records, valuation and accounting processes, due diligence, breach monitoring and governance.
The regulations require an IIO to have a Board-approved Investment Policy that addresses, among other matters, situations involving breaches and action plans to address them.
Accordingly, internal audit serves as an independent assurance mechanism for determining whether the investment framework established by management is actually operating as intended.
Key Areas to Be Covered in an IIO Investment Internal Audit
The scope of internal audit should be designed around the key requirements contained in the investment regulations.
Investment Policy and Governance
The auditor should first review whether a Board-approved Investment Policy is in place and whether actual investment activities are consistent with that policy.
The review may cover permitted asset classes, investment approval authority, delegation matrix, breach management and corrective-action mechanisms.
The functioning of the Investment Management Committee should also be evaluated, including its constitution, approvals, reporting processes and oversight of the investment portfolio.
Investment Eligibility and Jurisdiction
Each investment should be tested for regulatory eligibility.
The regulations permit IIOs to invest in IFSC, in India under the applicable RBI or SEBI framework, in the home jurisdiction of the parent entity subject to relevant requirements, and in other eligible overseas jurisdictions. Certain FATF high-risk jurisdictions are excluded.
The auditor should therefore verify both the type of investment instrument and the jurisdiction in which the investment is made.
Independent Due Diligence
External credit ratings alone are not sufficient.
Regulation 15 requires IIOs to conduct independent due diligence on proposed investments in addition to the rating given by rating agencies.
Internal audit should consequently examine whether appropriate financial, credit and risk assessments were performed before investments were approved.
Asset-Liability Alignment
The regulations require an IIO to earmark, invest and at all times maintain assets having a value not less than its liabilities.
Factors such as the nature, term or duration, currency and uncertainties of investments are specifically required to be considered.
Internal audit should therefore examine whether investment management appropriately considers liquidity, maturity and currency aspects in relation to insurance liabilities.
Valuation and Accounting
Regulation 5 requires IIOs to value their assets and liabilities and maintain the applicable solvency margin.
The internal auditor should review valuation methodologies, pricing or NAV sources, investment reconciliations and consistency between the investment register, custodian records, books of account and regulatory reporting.
Audit of Investment Exposure Limits
Testing regulatory exposure limits is one of the most important components of the internal audit.
Regulation 9 prescribes asset-class limits covering bonds, debt instruments, equities, AIFs, loans, property, infrastructure and money-market instruments. For example, listed equities and equity-type instruments are subject to a 20% exposure level, while Category I and II AIFs, loans, property and infrastructure are subject to specific lower limits.
The auditor must then consider additional layers of restrictions.
Regulation 10 prescribes exposure limits based on Insurance Capital Standards rating categories, while Regulations 11 to 13 apply sovereign-rating-linked limits to debt, equity, property and infrastructure exposures.
Regulation 14 further prescribes concentration limits:
| Exposure Category | Maximum Exposure |
|---|---|
| Single investee entity | 10% |
| IIO’s own group | 5% |
| Any other group | 15% |
| Particular industrial sector | 15% |
A key audit principle is that these limits should not be tested independently in isolation.
Review of Internal Controls and Investment Governance
Internal audit should also evaluate the design and operating effectiveness of the investment control environment.
The scope may include investment approvals, maker-checker controls, delegation of authority, dealing and settlement, custody, investment reconciliations, valuation controls, exception reporting and escalation of regulatory breaches.
A well-designed internal audit report should clearly classify observations into regulatory non-compliance, control deficiency, process weakness and improvement opportunity. This helps management and the Board prioritise corrective actions.
Frequently Asked Questions
- Is investment internal audit mandatory for an IIO in GIFT IFSC?
Yes. Regulation 16 specifically requires internal control systems including internal audits for investment, in addition to external audits. - How frequently should an IIO conduct investment internal audit?
The Investment Regulations require internal audit but Regulation 16 itself does not prescribe a specific frequency. The appropriate frequency should therefore be determined considering applicable regulatory directions and the size, complexity and risk profile of the investment portfolio. - What should an IIO investment internal audit cover?
The scope should generally include Investment Policy compliance, investment eligibility, regulatory exposure limits, due diligence, valuation, asset-liability considerations, internal controls and governance. - Should the internal auditor verify investment exposure limits?
Yes. Testing exposure limits under Regulations 9 to 14 is a core part of investment compliance review. - Is internal audit different from external audit?
Yes. Regulation 16 expressly refers to internal audits for investment in addition to external audits, making them distinct components of the overall assurance framework.
Conclusion
Internal audit under the IFSCA investment framework is more than a financial verification exercise. It provides assurance over investment eligibility, regulatory exposure limits, governance, due diligence, valuation and internal controls. For insurance and reinsurance offices operating in GIFT IFSC, a structured investment internal audit can help identify compliance gaps early, strengthen investment governance and improve preparedness for external audit and regulatory scrutiny.
